漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cri-o: cri-o path traversal in log handling functions allows arbitrary unmounting
Vulnerability Description
A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
CRI-O 路径遍历漏洞
Vulnerability Description
CRI-O是CRI-O开源的一款用于Kubernetes系统的轻量级容器运行时环境。 CRI-O存在路径遍历漏洞,该漏洞源于日志管理功能中的路径遍历问题,允许攻击者卸载任意主机路径,造成节点级拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A